7.8
CVSSv2

CVE-2007-3770

Published: 15/07/2007 Updated: 29/07/2017
CVSS v2 Base Score: 7.8 | Impact Score: 7.8 | Exploitability Score: 8.6
VMScore: 694
Vector: AV:N/AC:M/Au:N/C:C/I:P/A:N

Vulnerability Summary

The terminal_helper_execute function in terminal/terminal.c in Xfce Terminal 0.2.6 allows user-assisted remote malicious users to execute arbitrary commands via shell metacharacters in a crafted link, as demonstrated using the "Open Link" functionality.

Vulnerable Product Search on Vulmon Subscribe to Product

os-cillation xfce terminal 0.2.6

Vendor Advisories

Debian Bug report logs - #437454 CVE-2007-3770: execute arbitrary commands via crafted links using "Open Link" functionality Package: xfce4-terminal; Maintainer for xfce4-terminal is Debian Xfce Maintainers <debian-xfce@listsdebianorg>; Source for xfce4-terminal is src:xfce4-terminal (PTS, buildd, popcon) Reported by: Darr ...
Lasse Kärkkäinen discovered that the Xfce Terminal did not correctly escape shell meta-characters during “Open Link” actions If a remote attacker tricked a user into opening a specially crafted URI, they could execute arbitrary commands with the user’s privileges ...
It was discovered that xfce-terminal, a terminal emulator for the xfce environment, did not correctly escape arguments passed to the processes spawned by Open Link This allowed malicious links to execute arbitrary commands upon the local system For the stable distribution (etch), this problem has been fixed in version 0256rc1-2etch1 For the u ...